
Service
Windows forensics
What is examined
- NTFS metadata, journal entries and deleted file remnants
- Registry hives, user profiles and autostart entries
- Event logs, logon events and remote access
- Execution traces, USB history and connected storage media
How the examination is carried out
- 1.Acquisition through a write blocker, with verified hashes
- 2.Parsing of the artefact groups with independent tools
- 3.Cross-checking of contradictory timestamps
- 4.Documentation of findings, methods and remaining uncertainty
Technical limits
These limits are stated before the instruction, not afterwards.
- Event logs rotate and may no longer cover the period in question.
- Anti-forensic clean-up tools can remove artefacts irreversibly.
- Encrypted volumes without keys remain inaccessible.
- Timestamps can be manipulated; this is stated where it is detected.
FREQUENTLY ASKED QUESTIONS
Windows forensics: frequently asked questions
Often yes. Registry and log entries record device identifiers and connection times, provided the entries have not been removed or overwritten.
Analysis takes place on the secured working copy in the permanent examination rooms at the registered office in Krefeld, Germany. Devices are handed over in person or sent by insured carrier; by prior arrangement, processing in Munich is also possible. Where the technical conditions allow it, the acquisition itself can also be carried out at the client’s premises or at the location of the item; unavoidable changes to a running system are documented with reasons.
Whether an expert report is used in proceedings, and what evidential value it carries, is decided by the competent court or investigating authority. Our examinations are documented so that third parties can review them: recorded handover, cryptographic hashes, described methods and a clear separation between technical finding and assessment. A binding assurance of later admissibility cannot be given.
Equipment used
Systems used in this examination
- X-Ways Forensics
Analysis of Windows file systems, artefacts and timelines.
Next step
Discuss your case
Describe the situation briefly. We will say what can realistically be established, and what cannot.